News

2026-07-23 · Cybersecurity · Podcast

New episode: “All your data is already stolen” — on the Registrų centras leak and phone scammers

In the new episode I talk about something that now affects everyone: after the Registrų centras (State Enterprise Centre of Registers) leak, practically all of our data is already out there — and how phone scammers exploit it.

Watch the episode

If you think it could help someone close to you — especially older relatives, who scammers target most — share this episode. One share can save someone real money and stress.


Previous news

2026-06-30 · Cybersecurity

“I changed my password and turned on 2FA — and they’re still getting in through me”

This week I got a message from an acquaintance. I’m retelling it anonymously, because the story is one of the most common I see, and it’s probably relevant to more than one person.

In short: they downloaded something they shouldn’t have. One day someone broke into their Instagram and Discord, posted all sorts of things, and the system didn’t even show a login from elsewhere. They reinstalled Windows, everything seemed fine. A couple of days later — comments on TikTok in their name, “as if from a bot”. They changed passwords, turned on two-factor. But the feeling that “someone is still hanging over me” didn’t go away. No notifications, no “signed in from a new device”. As if everything were happening simply through them.

And here’s the key point I want people to understand:

This is not a simple password leak. This is an infostealer — a data thief.

This kind of malware steals more than passwords. It also steals your login “keys” — session access files (tokens, cookies) from the browser. And with those, the attacker doesn’t need your password. They simply use your already-open, already-authenticated session.

That’s why the victim feels trapped:

The person does everything the internet advises — changes the password, adds 2FA — and can’t understand why it doesn’t help. It doesn’t help because they’re solving the wrong problem.

What you actually need to do (and in exactly this order):

  1. Do everything from a CLEAN device. Not the one that was infected.
  2. If you reinstalled Windows — good. But don’t import old saved passwords and don’t restore the browser profile “from the cloud”. That brings the infection right back.
  3. Start with your main email — it’s the “master” account. Change the password, turn on 2FA, check that no one added mail-forwarding rules and that the recovery phone/email hasn’t been changed.
  4. For every account separately (Instagram, Discord, TikTok, Google, etc.):
    • change the password,
    • click “Log out of all devices / all sessions” — this is the most important step, it kills the stolen keys,
    • turn on 2FA via an app (authenticator), not via SMS,
    • review “Connected apps” and remove the ones you don’t recognise.
  5. Treat every password saved in the browser as stolen. Wherever it was reused — change it everywhere.

Two questions I get right away:

“So which antivirus should I buy?” — You don’t need to buy an expensive one. For a clean, updated Windows the built-in Microsoft Defender is enough, and free Malwarebytes works for a one-off scan. Money spent on a “premium” antivirus won’t solve this specific problem — killing the sessions does.

“Why isn’t 2FA over SMS good enough?” — SMS can be intercepted, and the number can be stolen through a so-called SIM swap (the scammer moves your number to their SIM). An authenticator app generates the code on the device itself, offline, so there’s nothing left to intercept.

The bottom line: if you feel like “someone is hanging over you” and changing the password doesn’t help — the problem is most likely not the password, but the open sessions. Those need to be closed.

Stay safe. And if you know someone this is happening to right now — forward it. It can save them a lot of stress.